Android Google Android Mobile operating system

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Google Android.

Recent Google Android Security Advisories

Advisory Title Published
2026-10-07 Chrome Releases: Chrome for Android Update (version 155) October 7, 2026
2026-10-02 Chrome Releases: Chrome for Android Update (version 154) October 2, 2026
2026-10-01 Android Security Bulletin—October 2026 October 1, 2026
2026-09-29 Chrome Releases: Chrome for Android Update (version 154) September 29, 2026
2026-09-22 Chrome Releases: Chrome for Android Update (version 154) September 22, 2026
2026-09-18 Chrome Releases: Chrome for Android Update (version 153) September 18, 2026
2026-09-16 Chrome Releases: Chrome for Android Update (version 153) September 16, 2026
2026-09-08 Chrome Releases: Chrome for Android Update (version 153) September 8, 2026
2026-09-04 Chrome Releases: Chrome for Android Update (version 152) September 4, 2026
2026-09-02 Chrome Releases: Chrome for Android (version 152) September 2, 2026

EOL Dates

Ensure that you are using a supported version of Google Android. Here are some end of life, and end of support dates for Google Android.

Release EOL Date Status
17 -
Active

16 -
Active

15 -
Active

14 -
Active

13 March 2, 2026
EOL

Google Android 13 became EOL in 2026.

12.1 March 3, 2025
EOL

Google Android 12.1 became EOL in 2025.

12 March 3, 2025
EOL

Google Android 12 became EOL in 2025.

11 February 5, 2024
EOL

Google Android 11 became EOL in 2024.

10 March 6, 2023
EOL

Google Android 10 became EOL in 2023.

9 January 1, 2022
EOL

Google Android 9 became EOL in 2022.

8.1 January 10, 2021
EOL

Google Android 8.1 became EOL in 2021.

8.0 January 1, 2021
EOL

Google Android 8.0 became EOL in 2021.

7.1 October 1, 2019
EOL

Google Android 7.1 became EOL in 2019.

7.0 October 1, 2019
EOL

Google Android 7.0 became EOL in 2019.

6.0 August 1, 2018
EOL

Google Android 6.0 became EOL in 2018.

5.1 March 1, 2018
EOL

Google Android 5.1 became EOL in 2018.

5.0 March 1, 2018
EOL

Google Android 5.0 became EOL in 2018.

4.4w October 1, 2017
EOL

Google Android 4.4w became EOL in 2017.

4.4 October 1, 2017
EOL

Google Android 4.4 became EOL in 2017.

4.3 -
Active

By the Year

In 2026 there have been 592 vulnerabilities in Google Android with an average score of 7.2 out of ten. Last year, in 2025 Android had 450 security vulnerabilities published. That is, 142 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.05




Year Vulnerabilities Average Score
2026 592 7.20
2025 450 7.26
2024 831 7.11
2023 1214 6.45
2022 1048 6.41
2021 575 6.72
2020 702 6.86
2019 491 7.08
2018 432 7.60

It may take a day or so for new Android vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Google Android Security Vulnerabilities

Android platform_msg_handler_init LPE via missing permission check
CVE-2026-56952 6.7 - Medium - October 06, 2026

In platform_msg_handler_init of default_msg_handlers.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

AuthZ

Out-of-Bounds Write in Wacom HID Driver Enables Physical Privilege Escalation
CVE-2026-56936 6.8 - Medium - October 06, 2026

In wacom_hid_set_device_mode of wacom_sys.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Buffer Overflow

UAF in eventpoll.c allows local privilege escalation
CVE-2026-56906 7 - High - October 06, 2026

In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Race Condition

Android Bluetooth UAF RCE via bluetooth_ccc.cc
CVE-2026-55330 9.8 - Critical - October 06, 2026

In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Dangling pointer

HWCrypto KDN Local Info Disclosure via Prot Logic Error
CVE-2026-55307 4.4 - Medium - October 06, 2026

In kdn_set_sysregs_prot of hwcrypto-kdn.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

Improper Privilege Management

Android gem_msg.c Permission Bypass (CVE-2026-0198)
CVE-2026-0198 4.4 - Medium - October 06, 2026

In is_pd_allowed of gem_msg.c, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

AuthZ

Android Settings Permission Bypass Confused Deputy Local Priv Escalation
CVE-2026-28648 7.8 - High - October 05, 2026

In Settings, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Confused Deputy

Android DeviceAdminApps PrivEsc via Permission Bypass
CVE-2026-28647 7.8 - High - October 05, 2026

In updateState of DeviceAdminAppsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Privilege Management

Android Local Escalation via Permission Bypass in ApplicationActionButtonsPref
CVE-2026-28641 7.8 - High - October 05, 2026

In shouldDisableUninstallButton of ApplicationActionButtonsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Privilege Management

Android Credential Storage Improper Input Permission Bypass
CVE-2026-28640 7.8 - High - October 05, 2026

In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Input Validation

Android Permission Bypass: Local Priv Escalation (CVE-2026-28625)
CVE-2026-28625 7.8 - High - October 05, 2026

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Privilege Management

Android btif_rc Race Condition Enables Local PrivEsc
CVE-2026-58880 7 - High - October 05, 2026

In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Race Condition

Android Telephony PduParser DoS via Missing Bounds Check
CVE-2026-58865 7.5 - High - October 05, 2026

In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Buffer Overflow

Android: Potential DoS via Uncaught Exception, Enables Local Priv Escalation
CVE-2026-58859 7.8 - High - October 05, 2026

In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Uncaught Exception

Android Camera3StreamSplitter OOB Read in Camera3StreamSplitter.cpp
CVE-2026-58856 3.3 - Low - October 05, 2026

In returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Buffer Overflow

Android OS Memory Corruption via Type Confusion Enables Local Priv Escalation
CVE-2026-58854 7.8 - High - October 05, 2026

In multiple locations, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Object Type Confusion

Android VirtualAudio Controller Local Priv Esc via Permission Bypass
CVE-2026-58841 7.8 - High - October 05, 2026

In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Privilege Management

Android BT Service Heap Buffer Overflow in cfg2prop
CVE-2026-58835 8.8 - High - October 05, 2026

In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Heap-based Buffer Overflow

Android DPMService DoS via Input Validation
CVE-2026-58834 5.5 - Medium - October 05, 2026

In setPermissionGrantState of DevicePolicyManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Input Validation

Android OOB Write in System Library Enables Local Priv Escalation
CVE-2026-58815 7.8 - High - October 05, 2026

In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Buffer Overflow

Android stpropnci OOB Write Enables Local Priv Escalation
CVE-2026-55286 7.8 - High - October 05, 2026

In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Buffer Overflow

Android OOB Write in uninitialized data, remote privilege escalation
CVE-2026-55280 8.8 - High - October 05, 2026

In multiple locations, there is a possible out-of-bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Use of Uninitialized Variable

Android dialInternal Confused Deputy PrivEsc
CVE-2026-55270 7.8 - High - October 05, 2026

In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Confused Deputy

Local Priv Escalation via Buffer Overflow in Android snoop_logger
CVE-2026-55269 7.8 - High - October 05, 2026

In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety issue due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Input Validation

OOBW in libufdt qsort (Android) local privilege escalation
CVE-2026-55266 7.8 - High - October 05, 2026

In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Resource Exhaustion

Android PduParser.java OOB Read Remote DoS
CVE-2026-55265 6.5 - Medium - October 05, 2026

In multiple functions of PduParser.java, there is a possible out of bounds read due to a missing bounds check. This could lead to a remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Buffer Overflow

Android MessageQueueBase.h OOB Read Enables Local Priv Escalation
CVE-2026-49937 7.8 - High - October 05, 2026

In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Buffer Overflow

Android Bluetooth Privileged Process Control-Flow Hijack via Uninitialized Pointer
CVE-2026-49933 7.8 - High - October 05, 2026

In handle_le_monitor_device_event of msft.cc, there is a possible control-flow hijack in the privileged bluetooth process due to an uninitialized pointer dereference. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Access of Uninitialized Pointer

Android NFC rw_t4t OOB Write via Integer Overflow
CVE-2026-49885 7.8 - High - October 05, 2026

In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Integer Overflow or Wraparound

Android OOB Write in nfa_nfcee_act.cc for Priv Esc
CVE-2026-49880 7.8 - High - October 05, 2026

In multiple functions of nfa_nfcee_act.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Buffer Overflow

Android wpa_supplicant OOB Write in robust_av.c Enables RCE
CVE-2026-49878 7.2 - High - October 05, 2026

In wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.

Memory Corruption

Android WifiPermissionsUtil Sandbox Escape - Priv Escalation
CVE-2026-45524 8.8 - High - October 05, 2026

In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

AuthZ

Android OOB Read in rw_t5t.cc Leads to Local Info Disclosure
CVE-2026-28667 5.5 - Medium - October 05, 2026

In multiple functions of rw_t5t.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Buffer Overflow

Qualcomm DOS via Transient Frame Parsing in Channel Usage
CVE-2026-25294 7.4 - High - September 17, 2026

Transient DOS while parsing frame during channel usage.

Buffer Over-read

Qualcomm WLAN Driver Transient DoS via Invalid FILS IE Header Length
CVE-2026-25275 7.5 - High - September 17, 2026

Transient DOS when processing authentication frames with invalid FILS information element header lengths.

Buffer Over-read

Qualcomm Bluetooth Transient DOS via Insufficient Channel Map with AFH Enabled
CVE-2026-24081 7.4 - High - September 17, 2026

Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.

Buffer Over-read

In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check
CVE-2026-58773 6.7 - Medium - September 15, 2026

In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Memory Corruption

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-58767 6.7 - Medium - September 15, 2026

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-58766 7.8 - High - September 15, 2026

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In GPU, there is a possible permission bypass due to a logic error in the code
CVE-2026-58765 6.7 - Medium - September 15, 2026

In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-58755 6.7 - Medium - September 15, 2026

In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code
CVE-2026-58751 6.7 - Medium - September 15, 2026

In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Dangling pointer

In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code
CVE-2026-58747 6.7 - Medium - September 15, 2026

In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In multiple locations, there is a possible escalation of privilege due to improper input validation
CVE-2026-58744 7.8 - High - September 15, 2026

In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Input Validation

In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy
CVE-2026-58739 6.7 - Medium - September 15, 2026

In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Confused Deputy

In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition
CVE-2026-58734 7 - High - September 15, 2026

In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Memory Corruption

In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data
CVE-2026-58731 6.2 - Medium - September 15, 2026

In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Use of Uninitialized Variable

In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition
CVE-2026-58728 7 - High - September 15, 2026

In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Race Condition

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check
CVE-2026-58726 6.7 - Medium - September 15, 2026

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In multiple locations, there is a possible use-after-free due to a race condition
CVE-2026-58724 7 - High - September 15, 2026

In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Dangling pointer

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Google Android or by Google? Click the Watch button to subscribe.

Google
Vendor

Google Android
Mobile operating system

subscribe